Skip to content
complisto

Legal

Privacy Policy

Last updated: August 22, 2026 · Operator: Hanov Consulting

Read this first — non-negotiable clauses

These provisions describe how Complisto handles the data flows required to run the product. They apply in addition to (and override any conflicting language in) the policy body below.

Google OAuth data flow

When you sign in with Google, Complisto receives — via Google's OAuth 2.0 flow — your email address, display name, and profile picture URL. We use these fields solely to identify your session, display your identity in-product, and associate scans with your account. We do not sell this data, do not use it for advertising, and do not share it with third parties except processors necessary to operate the service (see “Sub-processors” below).

What we store

  • Authentication identity from Supabase Auth (id, email, provider).
  • Business profile you enter on a scan (business name, address, vertical, evidence attestations).
  • Scan and finding records tied to your user id when you are signed in; anonymous scans are stored without a user id.
  • Waitlist and email-fallback addresses you submit.
  • Server logs (IP, user agent, timestamps) for security and abuse prevention.

Retention

Authenticated scan records last for the life of the account. Deleting your account in Settings immediately removes your scans, waitlist email, and Google auth user. Anonymous scans are retained for ninety (90) days. Server logs are rotated within thirty (30) days. Email privacy@complisto.com if you need us to finish a deletion that did not complete in-app.

Your rights

Subject to applicable law (including GDPR and CCPA where they apply), you may request access to, correction of, or deletion of your personal data by emailing privacy@complisto.com. We respond within thirty (30) days.

Sub-processors

  • Supabase — authentication and Postgres storage (US).
  • Google — OAuth 2.0 identity provider (per Google's own privacy terms).
  • Hostinger — application hosting (VPS).
  • Resend — transactional email delivery (planned; not yet active).

No ads, no sale of personal data

Hanov Consulting does not run advertising, does not participate in ad networks, and does not sell personal data to third parties.

Cookies and local storage

Complisto uses first-party cookies and browser local storage to keep you signed in and to remember the last business you scanned so we can render your dashboard without re-fetching. We do not use third-party advertising cookies. Supabase Auth sets the session cookies; you can clear them at any time from your browser settings.

International transfers

Complisto's infrastructure (Supabase, Hostinger) is hosted in the United States. If you access the service from outside the US, your information is transferred to the US and handled under this policy. Where required by law (GDPR, UK GDPR), we rely on Standard Contractual Clauses with our sub-processors.

Children

Complisto is intended for adult business owners. We do not knowingly collect personal information from children under 16. If you believe we have, contact privacy@complisto.com and we will delete it.

Changes to this policy

Material changes will be announced in-product or by email to your account address at least 14 days before they take effect. The “Last updated” date above changes with each material revision.

Questions? Contact privacy@complisto.com. See also our Terms of Service and Disclaimer.
Privacy Policy — Complisto